Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 16 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 15 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift_gitops:1.16::el8 cpe:/a:redhat:openshift_gitops:1.17::el8 |
|
| References |
|
Mon, 15 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift_gitops:1 |
Mon, 15 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Mon, 15 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster. | |
| Title | Openshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobs | |
| First Time appeared |
Redhat
Redhat openshift Gitops |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:/a:redhat:openshift_gitops:1 cpe:/a:redhat:openshift_gitops:1.18::el8 |
|
| Vendors & Products |
Redhat
Redhat openshift Gitops |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-12-15T20:10:59.040Z
Reserved: 2025-12-02T15:18:16.323Z
Link: CVE-2025-13888
Updated: 2025-12-15T15:50:13.357Z
Status : Awaiting Analysis
Published: 2025-12-15T16:15:50.333
Modified: 2025-12-15T20:15:48.937
Link: CVE-2025-13888
OpenCVE Enrichment
No data.